Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-23922

Опубликовано: 22 апр. 2021
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

A flaw was found in giflib. A missing check in function DumpScreen2RGB in gif2rgb.c leads to an out-of-bounds read, allowing an attacker to crash the gif2rgb tool. The issue is not in the giflib library, but in the gif2rgb utility program.

Отчет

This Moderate impact flaw affects the gif2rgb utility, not the giflib library. A missing bounds check in 'DumpScreen2RGB()' can lead to an out-of-bounds read when processing a crafted GIF file, causing the tool to crash. Exploitation requires local access and user interaction.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6giflibOut of support scope
Red Hat Enterprise Linux 7giflibOut of support scope
Red Hat Enterprise Linux 8giflibNot affected
Red Hat Enterprise Linux 9giflibAffected
Red Hat AI Inference Server 3.2rhaiis/model-opt-cuda-rhel9FixedRHSA-2026:412809.03.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1953004giflib: out-of-bounds read in DumpScreen2RGB() in gif2rgb.c in gif2rgb tool

EPSS

Процентиль: 82%
0.02237
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

CVSS3: 7.1
nvd
больше 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

CVSS3: 7.1
debian
больше 5 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif ...

CVSS3: 7.1
github
больше 4 лет назад

An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read.

EPSS

Процентиль: 82%
0.02237
Низкий

7.1 High

CVSS3